Storm-2372 is a threat actor documented by Microsoft in February 2025, known for using messaging and Teams-style lures to trick victims into entering attacker-provided device codes, leading to account takeover. The group's tradecraft has been adopted by other actors through reusable tooling like DEBULL.